Every prompt you send leaves the building. Most of the time that is fine. Four kinds of content make it a breach, a licence problem, or a dead deal, and there is no undo button. This module draws the red lines so hard you can't miss them, then makes you classify real pastes under pressure.
THE BRUTAL TRUTHThe moment a player's name, a live API key, or the unsigned operator deal is in that text box, you have handed it to a third party you do not control. Their promise not to train on it changes nothing about their logs, their breaches, or our obligations under GDPR and our licences. There is no recall. There is a regulator, a lawyer, and Ondrej.
The four red lines
Not guidelines. Lines. Crossing one is the same category of mistake as pushing to production without tests, except you cannot roll it back. Each card tells you what it looks like in real THG work, why it cracks the company, and what you do instead.
HOW IT CRACKS THE COMPANYA live token in a prompt is a live token in a vendor's logs, and in the screenshot you took to ask for help, and in the browser history. Whoever gets it is us until we notice. Rotating every key it touched is a day of work for three people, and that is the good outcome.
DO THIS INSTEADReplace every value with a placeholder before pasting: CF_TOKEN=<REDACTED>. The AI needs the shape of the config, never the value. If a value slipped through: rotate it now, then tell Tico. In that order, within five minutes.
Raw player PII
Anything that identifies a real player, or could when combined.
Looks like: names, emails, phone numbers, addresses, IBANs and card fragments, KYC documents, IP addresses, player IDs paired with anything, deposit and withdrawal history for identifiable people, support tickets as received, chat logs.
HOW IT CRACKS THE COMPANYThat is a personal data breach under GDPR the moment it leaves. Reportable to the supervisory authority within 72 hours. The Malta Gaming Authority and every operator whose players are in that CSV get a very uncomfortable email. Fines run to a percentage of turnover, and the licence review is worse than the fine.
DO THIS INSTEADAnonymise before pasting: PLAYER_1, <EMAIL>, round or drop the amounts. Keep the substance (the complaint, the pattern), drop the identity. If you cannot separate them, the task does not go to an external AI. Full stop.
Confidential commercial data
Anything a competitor, an operator or a journalist would pay to read.
Looks like: unsigned or signed operator contracts, revenue‑share percentages, pricing, per‑operator GGR and volumes, pipeline and forecasts, M&A, unannounced titles and dates, partner negotiations, board material, anything marked confidential.
HOW IT CRACKS THE COMPANYEvery operator contract has an NDA clause. "I pasted it into an AI to make the wording friendlier" is a breach of that clause, and the deal is now the operator's lawyer's problem, then ours. Unannounced titles leak the same way. Once it is out, "we asked the vendor to delete it" is not a defence anyone accepts.
DO THIS INSTEADRewrite the structure with fake numbers and fake names if you need help with wording. For real contract text, the path is Legal, not a chat window. If it has a confidentiality marking, that marking is the answer.
Security internals & other people's private data
Anything that draws an attacker a map, or exposes a colleague.
Looks like: pentest reports, unpatched vulnerability lists, internal hostnames and IP ranges, network diagrams, RNG and certification internals, incident post‑mortems with live details. Also: HR data, salaries, performance reviews, medical notes, private Slack DMs, anything under legal privilege.
HOW IT CRACKS THE COMPANYA pentest report is a to‑do list for whoever finds it. Certification internals are how we keep the RNG certified. And a colleague's performance review pasted "to soften the tone" is a GDPR breach against your own team, with a witness.
DO THIS INSTEADDescribe the class of problem in the abstract ("a REST endpoint returns stack traces on malformed JSON") without our hostnames or our findings. For HR and legal material: never. There is no redaction that makes a review about a named person safe.
The test is one sentence: would I paste this on LinkedIn? If the honest answer is "obviously not", it does not go into an AI either. Same audience: strangers you don't control.
Why "the vendor says they don't train on it" is not a defence
What people tell themselves"It's the business tier. They don't train on our data. It's basically internal." Training is one of about six ways data leaks. Logs are retained. Vendors get breached. Subpoenas exist. Support staff see prompts. Your own screenshot goes to a Slack channel. And GDPR, the licence and the NDA do not have a "but the vendor promised" clause.
What is actually trueAnything you paste is disclosed to a third party at that moment. Our obligations attach at disclosure, not at training. The only content that is safe to disclose is content that was safe to disclose anyway. So the question is never "is this vendor trustworthy". It is "is this content sensitive". If yes, redact it or keep it out.
The working rules
Rule 1
Redact before you paste. Values become placeholders. People become labels. Amounts get rounded or dropped. Do it in your editor, not in your head.
Rule 2
Synthesise when you need data. Ten fake rows that look like the real ones teach the AI the shape just as well. Real rows teach the vendor our players.
Rule 3
Company‑provisioned tools and accounts only. Your personal free‑tier chat account has a different contract, different retention, and no way for us to audit it. Work goes through work tools.
Rule 4
Screenshots count. A screenshot of a dashboard with a player's balance in the corner is PII. Crop it. A screenshot of a terminal with a token in the scrollback is a credential. Don't.
Rule 5
When in doubt, don't, and ask. Tico or Ondrej will answer in minutes. The alternative is explaining it to a regulator in weeks.
Rule 6
If you already did it: five minutes, not five weeks. Rotate what can be rotated. Tell Tico immediately, with exactly what went where. Do not delete the chat and hope. Reporting a leak is a bad day. Hiding one ends a career and possibly a licence.
THE FIVE‑MINUTE PROTOCOL · YOU JUST PASTED SOMETHING YOU SHOULDN'T HAVE
Stop the session. Do not send another message; do not ask the AI to "forget it".
If it was a credential, rotate it now. Before you tell anyone. Every minute it is live, it is live.
Tell Tico, then Ondrej. One message: what, where, when, whether it was rotated. No softening.
Keep the evidence. The chat, the timestamp, the screenshot. Deleting it makes an incident into a cover‑up.
Write the two‑line lesson for the next person. That is the only part of this that is optional, and it isn't.
This cracks the company: three scenarios
Three real shapes of real mistakes. Pick one, press play, and watch the days tick past. Then watch how it should have gone. Each of these is a fifteen‑second decision at a keyboard.
thg · incident timeline · scenario 1
pick a scenario, then press ▶
Game: safe or not to paste?
Fifteen things people at THG actually want to paste into an AI. For each: SAFE as‑is, REDACT FIRST (paste after replacing the sensitive parts), or NEVER (does not go to an external AI in any form). Calling a NEVER "safe" counts as a breach. Calling a SAFE "never" is paranoia, still wrong: it means you will stop using the tool where it helps.
Target: 15/15 with zero breaches. A single breach in real life is the whole afternoon, at best.
Classify the paste
Score 0/0Breaches 0streak 0
Paste 1
Quiz: prove it
Five questions. You need 4 right (80%) to pass. Fail and you retake it. Only passes are recorded.
Module 7 quiz
THE ONE THING TO REMEMBERIf it is a secret, a player, a deal, or a colleague, it does not go into the box. Redact it or keep it out. And if you already pasted it: rotate, then tell Tico, within five minutes. Not five weeks.